Skip to main content

Threats Tagged 'ghsa-v2xh-2vp8-57h8'

View all threats tagged with 'ghsa-v2xh-2vp8-57h8'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: ghsa-v2xh-2vp8-57h8

Threats Tagged 'ghsa-v2xh-2vp8-57h8'

Click on any threat for detailed analysis and mitigation recommendations

### Summary Several remote-content download paths in Pydantic AI buffered the entire HTTP response body into memory before enforcing any size limit. An application that exposes the local web-fetch tool (`web_fetch_tool`, or the `WebFetch` capability's local fallback) to untrusted prompts can be driven to fetch an attacker-chosen URL that streams a very large body, exhausting process memory and crashing the worker. The same unbounded buffering applied to `FileUrl` media downloads (`ImageUrl`, `DocumentUrl`, `VideoUrl`, `AudioUrl`). This is an **availability** issue only. SSRF protections (scheme allowlist, private-IP and cloud-metadata blocking) are unaffected; there is no confidentiality or integrity impact. ### Details The download helpers read the full response body before applying content-size controls, so an existing text-length limit only truncated *after* the whole body was already in memory, and media downloads had no wire-level cap at all. A single large response could grow process memory without bound . ### Who Is Affected You are affected if your application registers the local web-fetch tool (or relies on the `WebFetch` capability's local fallback) and exposes the agent to untrusted prompts, or if it downloads large remote `FileUrl`s influenced by untrusted input. Applications that only fetch developer-controlled URLs are not exposed to the model-chosen attack path. ### Remediation Upgrade to `2.24.0` or later (v2) or `1.107.2` or later (v1). Patched versions enforce a default 50 MiB cap on web-fetch and `FileUrl` downloads while streaming; pass `None` to the limit to restore the previous unbounded behavior. ### Credits Identified during internal review of media-download hardening.

Join the discussion

Showing 1 to 1 of 1 result

Filters:Tag: ghsa-v2xh-2vp8-57h8
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses